SOX Optimization: Improving Compliance Efficiency and Effectiveness

Size: px
Start display at page:

Download "SOX Optimization: Improving Compliance Efficiency and Effectiveness"

Transcription

1 SOX Optimization: Improving Compliance Efficiency and Effectiveness

2 This publication contains general information only and Deloitte & Touche LLP is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte & Touche LLP, its affiliates and related entities shall not be responsible. 2

3 SOX Optimization: Improving Compliance Efficiency and Effectiveness In initially implementing the provisions of the Sarbanes-Oxley Act of 2002 (SOX), many companies faced serious dilemmas in striking a balance between complying with the regulations, keeping costs down, and attempting to garner benefits around improved internal controls. Many also sought to leverage the requirements to result in a competitive advantage and increased shareholder value. Such concerns have been expressed by many participants in 1 recent Deloitte Dbriefs for Financial Executives webcasts and in the comment letters that registrants sent to the Securities and Exchange Commission (SEC) and Public Company Accounting Oversight Board (PCAOB) regarding the December 2006 Section 404-related proposals. The SEC approved its final management guidance related to internal control assessments on May 23, The PCAOB approved its revised auditing standard for audits of internal control over financial reporting on May 24, 2007; the standard will be final when approved by the SEC. While the implications of the new guidance will vary based on a registrant s specific circumstances, generally speaking, companies should benefit from the fact that management will have specific guidance it can apply in its Section 404 processes. Further, the new guidance allows both management and auditors to focus on the areas of greatest risk. Additionally, the approved guidance includes significant investor safeguards, will preserve audit quality, and should help make Section 404 implementation more efficient. For those companies attempting to attain compliance efficiencies and leverage improvement opportunities, a critical element lies in understanding the intersection of compliance management with performance management. Those companies that don t view Section 404 as a separate project, but rather embed compliance activities into ongoing operations, should attain superior results. 1 Deloitte refers to one or more of Deloitte Touche Tohmatsu, a Swiss Verein, its member firms, and their respective subsidiaries and affiliates. As a Swiss Verein (association), neither Deloitte Touche Tohmatsu nor any of its member firms has any liability for each other s acts or omissions. Each of the member firms is a separate and independent legal entity operating under the names Deloitte, Deloitte & Touche, Deloitte Touche Tohmatsu, or other related names. Services are provided by the member firms or their subsidiaries or affiliates and not by the Deloitte Touche Tohmatsu Verein. Deloitte & Touche USA LLP is the U.S. member firm of Deloitte Touche Tohmatsu. In the United States, services are provided by the subsidiaries of Deloitte & Touche USA LLP (Deloitte & Touche LLP, Deloitte Consulting LLP, Deloitte Financial Advisory Services LLP, Deloitte Tax LLP, and their subsidiaries), and not by Deloitte & Touche USA LLP.

4 The CFO s Quandary The enactment of SOX placed great pressure on companies in general and CFOs in particular. During the first year, the demands to meet the basic requirements of the law meant that, rather than using SOX as a catalyst for business improvement, many companies struggled simply to comply. Out of necessity, some organizations focused on short-term results (compliance) rather than a long-term strategy (driving continuous improvement). Many SOX efforts lacked a consistent, methodical process. Companies had little inkling how to prioritize. This often created major expenses and many headaches. In year two and subsequent years, the issue of cost landed on the CFO s doorstep. The perception: compliance was too expensive. The mandate: CFOs must cut costs. The quandary: how to reduce costs without jeopardizing compliance. The resultant attempts to address this dilemma often lacked methodological rigor, and the outcomes were frequently unsatisfactory. In an effort to rein in compliance costs, many companies were stymied, uncertain whether they could safely cut controls, and, if so, unsure which controls to cut and which to retain. Efficiency and effectiveness in internal control over financial reporting was not attained. Top-Down, Risk-Based Approach A top-down, risk-based approach has been endorsed by the PCAOB and the SEC as a means to attain efficiency and effectiveness of internal control over financial reporting. A key component of this strategy is the understanding that not all risks, accounts, and transactions are equally important (a theme that we address 2 in our Risk Intelligent Enterprise series of publications ). Also important are the principles that top-level, company-wide controls can have a more pervasive impact than lower-level, process-based controls; and that relevance and materiality should be key considerations in control testing plans. How does the top-down, risk-based concept apply in the real world? Take payroll as an example. Because wages and salaries are typically a large expense item for most organizations, many companies have documented all of the controls within the payroll cycle, and are typically doing extensive testing of these controls, including sampling of individual transactions. While there may be instances where this is an appropriate approach, for many companies applying a top-down, risk-based approach will reveal that payroll is highly routine, systematic, and predictable, is not subject to management estimates, and thus carries little risk of financial misstatement. When those normal conditions apply, then testing and documentation in this area can potentially be reduced by placing greater reliance upon management s periodic monitoring procedures. Why Top Down? Why focus on top-level controls? Because, like mountain snow feeding valley streams, everything flows from the top. Controls at the company-level can have an encompassing influence over controls at the process, transaction, or application level. Furthermore, controls that apply to all locations and business units help to set consistent standards and expectations across the company. Company-level controls include items such as tone at the top; policies and procedures; codes of conduct; the assignment of authority and responsibility; management s risk assessment process. Also in this category are controls that monitor other controls, such as oversight and assessment of the internal audit function, the audit committee, and employee selfassessment and fraud prevention activities, such as whistleblower hotlines, which can have an indirect relationship to financial statement misstatement risk. In addition, many companies have the opportunity to significantly increase their reliance upon company-level controls that can directly mitigate financial statement misstatement risk, including controls over the period-end financial reporting process; monitoring controls such as analytical review and budgeting; and controls governing centralized processing, such as shared service environments. 2 For more information on The Risk Intelligent Enterprise, visit 2

5 Deloitte & Touche LLP s SOX Optimization Approach According to a February 2007 poll of Deloitte Dbriefs webcast 3 viewers, almost 60 percent of surveyed companies plan to consider or revisit control rationalization as a result of the SEC s proposed guidance. A majority (53 percent) of companies are also considering changes to their testing strategy and levels of documentation as a result of the SEC s proposed guidance. Deloitte & Touche LLP (Deloitte & Touche) believes companies should adopt a risk-based control rationalization approach as part of a larger effort towards SOX optimization. A key element of SOX optimization is control rationalization. What, exactly, do we mean by control rationalization? Simply, we mean that not all controls are created equal. Some are more strategically important; some address more significant risks. Because of this inequality, controls should analyzed and prioritized, starting with the highest-level controls used by management to ensure reliable financial reporting. In conducting this assessment, the internal control and finance teams should pose a number of questions: What control objectives are addressed by these controls? Are they sufficiently detailed to provide the required level of assurance? What would be the impact of the failure of these controls? Is there sufficient evidence of the performance of these controls? By answering these and other questions, the team will be rationalizing the existing internal controls and better aligning their internal control structure with risk with the goal of retaining only the most strategic, efficient, and effective. Does your company plan to consider or revisit control rationalization as a result of the SEC s proposed guidance? Votes Received: 2426 Don t know or N/A 32.7% No 7.9% Yes 59.4% Is your company considering changes to its testing strategy and levels of documentation as a result of the SEC s proposed guidance? Votes Received: 2420 Don t know or N/A 34.0% This approach focuses on the continuous process of designing and deploying only the most effective and efficient controls to address financial reporting risks. Control rationalization applies a topdown, risk-based approach; eliminates unnecessary controls; uses risk-based testing plans; and optimizes the design of company-level and automated controls. It s important to note that because control requirements will change as the business changes, control rationalization should be approached as a multi-year, continuous effort that should be integrated into the company s operations. It can bring immediate benefits, but companies can achieve even more significant cost savings by adopting a long-term strategic approach to sustained compliance. No 12.6% Yes 53.4% 3 The Feb. 9, 2007 Dbriefs for Financial Executives webcast was attended by 3453 business executives. The demographic breakdown included 45% manager level; 27% executive level; and 24% analyst level. Industries represented included financial services 25%; technology, media, and telecommunications 16%; consumer business 13%; manufacturing 12%; energy and resources 9%; and life sciences and healthcare 7%. Due to the fact that survey participants self selected, and thus do not represent a random sampling, the survey results are not statistically valid and should not be relied upon. Nonetheless, the data represents the collective thoughts and experiences of business people at scores of companies, and the accompanying interpretations are based on the experiences and the views of a number of partners and principals of Deloitte & Touche LLP. 3

6 Leveraging Technology Effectively leveraging technology can help optimize a company s SOX effort in several areas, including the following: 1. Greater reliance can be placed upon testing of general computer controls and automated controls. In addition to helping management reduce its manual testing of routine systematic controls, increased reliance upon general computer controls and automated controls can allow management to focus its testing efforts in areas where changes have occurred or areas where there is greater risk due to non-routine processing, complexity, or level of judgment. At the same time, management can potentially reduce its effort in areas where the nature of the process or significant changes have not occurred. 2. Technologies can be leveraged to enhance the efficiency and effectiveness of management s testing efforts. This includes the use of file interrogation and continuous control monitoring technologies that can analyze entire populations of transactions for potential anomalies. These technologies can also help to augment management s anti-fraud programs and controls. 3. Technology can also be used to improve effectiveness and efficiency of management s overall compliance effort, including the following key areas: Creating a common repository for all key elements of risk (including operational and strategic risk areas). Providing integrated, enterprise-wide support for all compliance and risk management activities. Establishing a common repository for all controlsrelated documentation (including relevant policies and procedures). Allowing for centralized capture of assessment and testing activities. Providing automated support for management certifications. Many organizations are still primarily reliant upon spreadsheets, Word documents, and, in some cases, manual efforts to support their SOX initiatives. In other cases, companies are using point solutions that are solely designed to support SOX compliance and are not integrated with the company s key financial systems. Such methods are unnecessarily primitive. In the last few years, the sophistication of compliance technology has improved dramatically. 4 In a March 2007 Deloitte Dbriefs for Financial Executives webcast on compliance management, 49 percent of the surveyed participants said that technology tools are essential for the integration of compliance and performance. Attendees reported that the biggest challenge to integrating compliance within core processes lies in three areas: 1) organizational resistance or inertia 2) lack of sponsor or champion 3) need for a compelling business case. How do you view the role of IT in integrating the management of performance, risk, and compliance? Votes Received: 845 Technology is essential, and can be used now to enable integration of compliance and performance 49.3% Don t know/ N/A 12.0% While it may help in certain areas, I do not see technology as playing a critical role 4.5% Technology will be essential, but it will be several years or more before it will be up to the task 34.2% 4 The March 22, 2007 Dbriefs for Financial Executives webcast was attended by 1213 business executives. The demographic breakdown included 43% manager level, 29% executive level, and 24% analyst level. Industries represented included financial services 27%; technology, media, and telecommunications 17%; consumer business 11%; manufacturing 12%; energy and resources 8%; and life sciences and healthcare 9%. Due to the fact that survey participants self selected, and thus do not represent a random sampling, the survey results are not statistically valid and should not be relied upon. Nonetheless, the data represents the collective thoughts and experiences of business people at scores of companies, and the accompanying interpretations are based on the experiences and the views of a number of partners and principals of Deloitte & Touche LLP. 4

7 Four-Phase SOX Optimization Approach Deloitte & Touche has developed a four-phase approach to help companies optimize their SOX compliance work to achieve efficiency and effectiveness. The first two phases of this riskbased approach are tactical/short term. These phases can help the company generate immediate reductions in compliance costs and build a foundation for a sustainable internal control program. The last two phases go beyond the basic compliance requirement and may require a greater resource investment. But the payout can yield significant rewards. Deloitte & Touche s SOX Optimization Approach includes the following goals: Understand the overall design and balance of controls and how they align with financial reporting risks. Shift focus toward higher risk areas to enhance compliance quality. Achieve cost savings by applying more efficient compliance efforts for routine processing-related controls. Identify how company-level (as opposed to process-level) controls can be improved to drive compliance efficiencies and reduce the organization s overall compliance risk profile. Phase 1: Apply Top-Down, Risk-Based Scoping Approach Using SEC/PCAOB Guidance This phase begins with a risk assessment to understand the company s financial reporting risks and to identify and possibly reconsider the design of controls. Through this process, companies can scope appropriate areas into the compliance program and develop a process where in scope areas receive the amount of attention commensurate with their level of risk. Phase 2: Rationalize Existing Controls and Redesign Test Plans In this phase, companies rationalize both process-level and general computer controls; identify opportunities for enhancing control effectiveness; and consider removing redundant process-level controls from compliance testing. Phase 2 also involves applying a risk-based approach toward testing, which varies the timing, nature, and extent of testing based on the assessed risk. As a result, companies can direct their resources toward testing controls related to the highest risk areas, while minimizing the testing of controls in low-risk areas. Phase 3: Leverage Automated Controls and Enabling Technology In this phase, companies replace manual controls with automated controls (which are less prone to error and the potential performance problems associated with people-based controls). Automated controls can decrease costs and are usually easier and cheaper to test than manual controls. They also provide more reliability and can serve as monitoring controls. Continuous controls monitoring technology can be used in a number of business processes such as payroll, general ledger, purchasing cards, and travel and entertainment. Besides cost reduction and assurance regarding compliance status, what do you see as the greatest potential long-term benefit to integrating compliance within core processes? Votes Received: 962 All of the above 52.0% Don t know/ N/A 6.2% Improved focus on controls 7.6% Stronger ethical culture 3.4% Streamlined and more efficient processes 22.8% Better visibility into the impact of compliancedriven controls on business process performance 8.0% Phase 4: Standardize and Centralize Processes/GRC Integration The value derived from standardizing and centralizing processes and controls extends beyond compliance into day-to-day operational efficiencies. This phase focuses on integrating governance, risk, and compliance (GRC) activities in order to reduce costs, drive value, and improve overall risk management. 5

8 The payoff from standardizing and centralizing disparate processes and controls can be significant compared to the three earlier phases, although accomplishing this will be a lengthier process. A survey conducted during a March 2007 Deloitte Dbriefs for Financial Executives webcast validates this claim. Attendees polled during the webcast identified a number of long-term benefits derived from integrating compliance within core processes, including streamlined and more efficient processes, improved focus on controls, and stronger ethical culture. Organizations that integrate GRC practices will discover it can be a key driver of shareholder value. However, this initiative requires strong leadership from the C-suite and the board. An integrated approach to GRC can help to improve the overall Risk Intelligence of an organization and enable the use of risk offensively, as opposed to defensively. This includes more effectively managing the risks associated with the critical operations or key strategic initiatives that are long-term value drivers. Action Plans Organizations need to consider the impact that the SEC s guidance may have on documentation, testing strategy, and design of internal control over financial reporting. The following are a few steps that can be taken in this direction: 1. Revisit risk assessment from a top-down, risk-based perspective. At the account and business process level, increase focus on the assessment of qualitative risk factors, such as subjectivity to estimates and nature of processing, as opposed to focusing primarily on quantitative factors, such as size of balance. Consider or revisit control rationalization. Focus on those controls that, should they fail, would materially impact the financial statements. Look first at company-level controls (especially those that directly relate to financial reporting risks) before focusing on departmental and process-level controls. 2. Recognize that your approach can and, in most cases, should be different than that of the auditor. Communicate with your auditor regularly through the process, but, in general, do not replicate his or her work. Determine in what areas the auditor can rely on your work, and where the auditor must test independently. 3. Increase the level of ownership within the organization for internal controls. Implementing a program of control selfassessments can significantly augment and enhance control testing work, while at the same time reinforcing the need for responsibility and accountability with the most important person in the control structure the control owners themselves. Take some of the responsibility for control testing off the shoulders of internal audit, and imbed control testing and monitoring into daily operations. Deploy internal audit intelligently to maintain a balance of objectivity and ownership: management should get assurance from process owners; internal audit should provide reassurance in areas of greatest risk. 4. Focus on reducing effort. Investigate automated controls, which are generally more reliable, less costly, and more easily tested than their manual equivalents. Look for efficiency in control design. 5. Discuss revised plans and contemplated changes with the external audit team to help assess how these changes may affect the audit process. Springboard to Improvement A program of SOX optimization and control rationalization can help companies overcome the quandary of how to improve controls while simultaneously cutting costs and do so without jeopardizing compliance. Examples abound. In 2006, we authored an article in Harvard Business Review that illustrated the tangible benefits realized by several companies including Kimberly Clark, PepsiCo, and Sunoco that adopted a SOX optimization program 5. More 6 recently, we published an article in CRO magazine that discussed the benefits of improving controls efficiency and quality. Compliance with SOX and other regulatory requirements presents both burdens and opportunities. Forward-thinking companies will use the mandate as a springboard for taking an integrated, enterprise approach to Governance, Risk and Compliance, improving the overall Risk Intelligence of the organization. 5 Harvard Business Review, The Unexpected Benefits of Sarbanes-Oxley, April For a free copy, visit 6 Corporate Responsibility Officer (CRO) magazine, SOX Benefits, March 2007: 6

9 Resources For more information on Deloitte & Touche s SOX optimization approach, visit or contact your Deloitte & Touche partner. For more information on the concept of Risk Intelligence, visit Contacts Tom Connors Partner, Audit & Enterprise Risk Services National Leader of SOX Consulting Services, Audit & Enterprise Risk Services Deloitte & Touche LLP tconnors@deloitte.com Stephen Wagner Managing Partner, U.S. Center for Corporate Governance Innovation Leader, Audit & Enterprise Risk Services Deloitte & Touche LLP swagner@deloitte.com 7

10 Dbriefs for Financial Executives We invite you to visit to join the Deloitte Dbriefs webcast series. The Financial Executives series helps you stay on top of all the latest issues and strategies in: Corporate Governance Driving Enterprise Value Financial Reporting Private Companies Sarbanes-Oxley Transactions & Business Events Dbriefs Webcasts Relating to Compliance and Sarbanes-Oxley Section 404: What does the New Guidance Mean to You? June 28, 2007 Governance, Risk, and Compliance: Evaluating Strategy, Structure, and Costs May 24, 2007 The Next Stage of Section 404: Opportunities for Management to Optimize Efforts April 26, 2007 The Intersection of Compliance Management and Performance Management March 22, 2007 Extracting Lasting Benefits from Compliance Efforts February 22, 2007 Special Edition Webcast Section 404: What do the Proposed Changes Mean to You? February 9, 2007 CPE credits are offered to viewers of original live webcasts, but are not available for viewing archived programs. Archived webcasts are available for 180 days after the live presentation. 8

11 7

12 #7230 About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu, a Swiss Verein, its member firms, and their respective subsidiaries and affiliates. Deloitte Touche Tohmatsu is an organization of member firms around the world devoted to excellence in providing professional services and advice, focused on client service through a global strategy executed locally in nearly 140 countries. With access to the deep intellectual capital of approximately 150,000 people worldwide, Deloitte delivers services in four professional areas audit, tax, consulting, and financial advisory services and serves more than 80 percent of the world s largest companies, as well as large national enterprises, public institutions, locally important clients, and successful, fast-growing global companies. Services are not provided by the Deloitte Touche Tohmatsu Verein, and, for regulatory and other reasons, certain member firms do not provide services in all four professional areas. As a Swiss Verein (association), neither Deloitte Touche Tohmatsu nor any of its member firms has any liability for each other s acts or omissions. Each of the member firms is a separate and independent legal entity operating under the names Deloitte, Deloitte & Touche, Deloitte Touche Tohmatsu, or other related names. In the United States, Deloitte & Touche USA LLP is the U.S. member firm of Deloitte Touche Tohmatsu and services are provided by the subsidiaries of Deloitte & Touche USA LLP (Deloitte & Touche LLP, Deloitte Consulting LLP, Deloitte Financial Advisory Services LLP, Deloitte Tax LLP, and their subsidiaries), and not by Deloitte & Touche USA LLP. The subsidiaries of the U.S. member firm are among the nation s leading professional services firms, providing audit, tax, consulting, and financial advisory services through nearly 40,000 people in more than 90 cities. Known as employers of choice for innovative human resources programs, they are dedicated to helping their clients and their people excel. For more information, please visit the U.S. member firm s Web site at Copyright 2007 Deloitte Development LLC. All rights reserved. Member of Deloitte Touche Tohmatsu

Integrating GRC with Performance Management Demands Enterprise Solutions

Integrating GRC with Performance Management Demands Enterprise Solutions As published in the April n May n June 2008 issue of Integrating GRC with Performance Demands Enterprise Solutions by Lee Dittmar, Principal, Deloitte Consulting LLP and Peter Vogel, Senior Manager, Deloitte

More information

Moving Forward with IT Governance and COBIT

Moving Forward with IT Governance and COBIT Moving Forward with IT Governance and COBIT Los Angeles ISACA COBIT User Group Tuesday 27, March 2007 IT GRC Questions from the CIO Today s discussion focuses on the typical challenges facing the CIO around

More information

Pulling it all together: Integrated Solutions for Governance, Risk and Compliance

Pulling it all together: Integrated Solutions for Governance, Risk and Compliance Customer Practice Profile Pulling it all together: Integrated Solutions for Governance, Risk and Compliance The business case for a new enterprise approach to GRC Integrated solutions for Governance, Risk

More information

Business Ethics and Compliance in the Sarbanes-Oxley Era A Survey by Deloitte and Corporate Board Member Magazine

Business Ethics and Compliance in the Sarbanes-Oxley Era A Survey by Deloitte and Corporate Board Member Magazine Business Ethics and Compliance in the Sarbanes-Oxley Era A Survey by Deloitte and Corporate Board Member Magazine Methodology The ethics and compliance survey was jointly conducted by Deloitte and Corporate

More information

Sarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers

Sarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers Sarbanes-Oxley Section 404: Compliance s for Foreign Private Issuers Table of Contents Requirements of the Act.............................................................. 1 Accelerated Filer s...........................................................

More information

Balance Sheet Integrity The Utopian Close: Creating a low risk, highly effective financial close

Balance Sheet Integrity The Utopian Close: Creating a low risk, highly effective financial close Balance Sheet Integrity The Utopian Close: Creating a low risk, highly effective financial close Balance Sheet Integrity: The Utopian Close creating a low risk, highly effective financial close 1 Executive

More information

[RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06]

[RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting

More information

AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS:

AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS: 1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF VIEWS AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN

More information

Risk Intelligence series. Creating a Risk Intelligent infrastructure Getting Risk Intelligence done

Risk Intelligence series. Creating a Risk Intelligent infrastructure Getting Risk Intelligence done Risk Intelligence series Creating a Risk Intelligent infrastructure Getting Risk Intelligence done Contents 3 Preface 3 Introduction 4 The Risk Intelligent Enterprise TM : A quick recap 7 Pillar one: Process

More information

Financial close, consolidation, and reporting Leveraging process alignment and Oracle Hyperion EPM Tools

Financial close, consolidation, and reporting Leveraging process alignment and Oracle Hyperion EPM Tools Financial close, consolidation, and reporting Leveraging process alignment and Oracle Hyperion EPM Tools Deloitte Consulting LLP 11 Today s finance organizations face multiple priorities that include the

More information

Sarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers

Sarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers Sarbanes-Oxley Section 404: Compliance s for Foreign Private Issuers As of March 14, 2005 Table of Contents Requirements of the Act.............................................................. 1 Accelerated

More information

Identity and Access Management Point of View

Identity and Access Management Point of View Identity and Access Management Point of View Agenda What is Identity and Access Management (IAM)? Business Drivers and Challenges Compliance and Business Benefits IAM Solution Framework IAM Implementation

More information

Sarbanes-Oxley Section 404: Management s Assessment Process

Sarbanes-Oxley Section 404: Management s Assessment Process Sarbanes-Oxley Section 404: Management s Assessment Process Frequently Asked Questions ADVISORY Contents 1 Introduction 2 Providing a Road Map for Management 3 Questions and Answers 3 Section I. Planning

More information

Auditing Standard 5- Effective and Efficient SOX Compliance

Auditing Standard 5- Effective and Efficient SOX Compliance Auditing Standard 5- Effective and Efficient SOX Compliance September 6, 2007 Presented to: The Dallas Chapter of the Institute of Internal Auditors These slides are incomplete without the benefit of the

More information

building a business case for governance, risk and compliance

building a business case for governance, risk and compliance building a business case for governance, risk and compliance contents introduction...3 assurance: THe last major business function To be integrated...3 current state of grc: THe challenges... 4 building

More information

Take the right steps 9 principles for building the Risk Intelligent Enterprise

Take the right steps 9 principles for building the Risk Intelligent Enterprise Take the right steps 9 principles for building the Risk Intelligent Enterprise Contents 9 principles for building a Risk Intelligent Enterprise 2 The Risk Intelligent Framework 4 1. Is risk a threat or

More information

M&A analytics The three-minute guide

M&A analytics The three-minute guide M&A analytics The three-minute guide M&A analytics The three-minute guide 1 Why it matters now Smarter decisions An M&A deal can be one of the biggest decisions a company makes, so it pays to do it right.

More information

Framing the future of corporate governance Deloitte Governance Framework

Framing the future of corporate governance Deloitte Governance Framework Framing the future of corporate governance Deloitte Governance Framework For those interested in the topic of corporate governance, these are dynamic times. The events of the past decade have led to the

More information

Fixed asset systems Why the tax function needs to have a stake in the game

Fixed asset systems Why the tax function needs to have a stake in the game Fixed asset systems Why the tax function needs to have a stake in the game ility enablers ablers While many tax functions do not own their organizations fixed asset systems, they do rely on access to current

More information

COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE

COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COMMITTEE OF SPONSORING ORGANIZATIONS (COSO) 2013 The Committee of Sponsoring Organizations (COSO) Internal Controls Integrated Framework,

More information

Impact of New Internal Control Frameworks

Impact of New Internal Control Frameworks Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region Bob.Jacobson@mcgladrey.com

More information

AUDIT OF READINESS FOR THE IMPLEMENTATION OF THE POLICY ON INTERNAL CONTROL

AUDIT OF READINESS FOR THE IMPLEMENTATION OF THE POLICY ON INTERNAL CONTROL AUDIT OF READINESS FOR THE IMPLEMENTATION OF THE POLICY ON INTERNAL CONTROL AUDIT REPORT JUNE 2010 TABLE OF CONTENTS EXCUTIVE SUMMARY... 3 1 INTRODUCTION... 5 1.1 AUDIT OBJECTIVE. 5 1.2 SCOPE...5 1.3 SUMMARY

More information

Internal Control Strategies. A Mid to Small Business Guide

Internal Control Strategies. A Mid to Small Business Guide Brochure More information from http://www.researchandmarkets.com/reports/2325460/ Internal Control Strategies. A Mid to Small Business Guide Description: Praise for Internal Control Strategies A Mid to

More information

SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners

SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners The Institute of Internal Auditors

More information

Data analytics and workforce strategies New insights for performance improvement and tax efficiency

Data analytics and workforce strategies New insights for performance improvement and tax efficiency Data analytics and workforce strategies New insights for performance improvement and tax efficiency Leading organizations today are shaping effective workforce strategies through the use of data analytics.

More information

Information Life Cycle Management (ILM)

Information Life Cycle Management (ILM) Information Life Cycle Management (ILM) Finding business value in Information Life Cycle Management (ILM): Proactive information management through ILM can reduce cost and risk while creating tangible

More information

On the Setting of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal

On the Setting of the Standards and Practice Standards for. Management Assessment and Audit concerning Internal (Provisional translation) On the Setting of the Standards and Practice Standards for Management Assessment and Audit concerning Internal Control Over Financial Reporting (Council Opinions) Released on

More information

U.S. CFO Program The Four Faces of the CFO. 2010 Deloitte Touche Tohmatsu

U.S. CFO Program The Four Faces of the CFO. 2010 Deloitte Touche Tohmatsu U.S. CFO Program The Four Faces of the CFO 2010 Deloitte Touche Tohmatsu CFOs Play Four Critical Roles in Companies Catalyze behaviors across the organization to execute strategic and financial objectives

More information

1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition

1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition 1. FPO Guide to the Sarbanes-Oxley Act: IT Risks and Controls Second Edition Table of Contents Introduction... 1 Overall IT Risk and Control Approach and Considerations When Complying with Sarbanes-Oxley...

More information

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP

IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/ Continuous Monitoring KPMG LLP IT Audit Perspective on Continuous Auditing/Continuous Monitoring INTRODUCTION New demands from the board, senior organizational

More information

An Oracle White Paper November 2011. Financial Crime and Compliance Management: Convergence of Compliance Risk and Financial Crime

An Oracle White Paper November 2011. Financial Crime and Compliance Management: Convergence of Compliance Risk and Financial Crime An Oracle White Paper November 2011 Financial Crime and Compliance Management: Convergence of Compliance Risk and Financial Crime Disclaimer The following is intended to outline our general product direction.

More information

Turning Information into Knowledge in a post-bradley Environment Monish Paul & Bhavesh Chavda

Turning Information into Knowledge in a post-bradley Environment Monish Paul & Bhavesh Chavda Turning Information into Knowledge in a post-bradley Environment Monish Paul & Bhavesh Chavda 12 November 2009 Agenda Monish Paul - The changing landscape : the burning platform for performance management

More information

February 2015. Sample audit committee charter

February 2015. Sample audit committee charter February 2015 Sample audit committee charter Sample audit committee charter This sample audit committee charter is based on observations of selected companies and the requirements of the SEC, the NYSE,

More information

National Association of State Comptrollers. Architecting a New State Operating Model for the Future. March 12, 2015

National Association of State Comptrollers. Architecting a New State Operating Model for the Future. March 12, 2015 National Association of State Comptrollers Architecting a New State Operating Model for the Future March 12, 2015 The world around us is changing at a dizzying pace. 2 National Association of State Comptrollers

More information

Getting to strong Leading Practices for value-enhancing internal audit By Richard Reynolds and Abhinav Aggarwal - PricewaterhouseCoopers LLP

Getting to strong Leading Practices for value-enhancing internal audit By Richard Reynolds and Abhinav Aggarwal - PricewaterhouseCoopers LLP Getting to strong Leading Practices for value-enhancing internal audit By Richard Reynolds and Abhinav Aggarwal - PricewaterhouseCoopers LLP Today's unpredictable business climate and challenging regulatory

More information

The Changing IT Risk Landscape Understanding and managing existing and emerging risks

The Changing IT Risk Landscape Understanding and managing existing and emerging risks The Changing IT Risk Landscape Understanding and managing existing and emerging risks IIA @ Noon Kareem Sadek Senior Manager, Deloitte Canada Chris Close Senior Manager, Deloitte Canada December 2, 2015

More information

Tax data analytics Gaining efficiency while addressing compliance

Tax data analytics Gaining efficiency while addressing compliance Tax data analytics Gaining efficiency while addressing compliance Increasingly, tax authorities in multiple countries are using data analytics tools to audit business tax data electronically. This trend

More information

Moving Internal Audit Back into Balance

Moving Internal Audit Back into Balance Moving Internal Audit Back into Balance A Post-Sarbanes-Oxley Survey Fourth Edition Table of Contents Introduction... 1 Executive Summary... 2 Overview of Rebalancing Initiatives... 4 Current Status of

More information

Supporting Compliance Management with Technology

Supporting Compliance Management with Technology Supporting Management with Technology May 27, 2009 Agenda Observations and challenges from the marketplace Process Overview of Tools to Support Understanding Your Requirements Closing Thoughts Questions?

More information

Fraud-Related Compliance

Fraud-Related Compliance Fraud-Related Compliance Areas of Compliance, Part 1: FCPA, SOX, PCAOB, Dodd-Frank 2015 Association of Certified Fraud Examiners, Inc. Foreign Corrupt Practices Act (FCPA) Enacted to prohibit corrupt payments

More information

ORACLE ENTERPRISE GOVERNANCE, RISK, AND COMPLIANCE MANAGER FUSION EDITION

ORACLE ENTERPRISE GOVERNANCE, RISK, AND COMPLIANCE MANAGER FUSION EDITION ORACLE ENTERPRISE GOVERNANCE, RISK, AND COMPLIANCE MANAGER FUSION EDITION KEY FEATURES AND BENEFITS Manage multiple GRC initiatives on a single consolidated platform Support unique areas of operation with

More information

Hedge fund launch considerations Reaching new boundaries. Investment Management

Hedge fund launch considerations Reaching new boundaries. Investment Management Hedge fund launch considerations Reaching new boundaries Investment Management There are people who make things happen, there are people who watch things happen, and there are people who wonder what happened.

More information

Sharing of Experience Section 404 Sarbanes-Oxley Act

Sharing of Experience Section 404 Sarbanes-Oxley Act Sharing of Experience Section 404 Sarbanes-Oxley Act 13th September 2005 Peter Koo Partner Deloitte Touche Tohmatsu CPA(HK), CA, AICPA, CISA, CISM, CIA,CFE, CRP Tel (HK): +852-2852-6507 Tel (China) : +86

More information

Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future

Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future BADM 590/395 IT Governance MS1 Professor Michael Shaw Submitted by: Amy Smith BA in MIS University of Illinois at Urbana-Champaign Smith

More information

The following is intended to outline our general product direction. It is intended for informational purposes only, and may not be incorporated into

The following is intended to outline our general product direction. It is intended for informational purposes only, and may not be incorporated into The following is intended to outline our general product direction. It is intended for informational purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any

More information

Insurance Industry Expertise

Insurance Industry Expertise Insurance Industry Expertise Delivered With High-Level Attention and Service Audit Tax Advisory Risk Performance The Unique Alternative to the Big Four For more than 50 years, clients in all sectors of

More information

Guide to Internal Control Over Financial Reporting

Guide to Internal Control Over Financial Reporting Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).

More information

Lowering E-Discovery Costs Through Enterprise Records and Retention Management. An Oracle White Paper March 2007

Lowering E-Discovery Costs Through Enterprise Records and Retention Management. An Oracle White Paper March 2007 Lowering E-Discovery Costs Through Enterprise Records and Retention Management An Oracle White Paper March 2007 Lowering E-Discovery Costs Through Enterprise Records and Retention Management Exponential

More information

XBRL & GRC Future opportunities?

XBRL & GRC Future opportunities? XBRL & GRC Future opportunities? Suzanne Janse Deloitte NL Paul Hulst Deloitte / Said Tabet EMC Presenters Suzanne Janse Deloitte Netherlands Director ERP (SAP, Oracle) Risk Management GRC software Paul

More information

Effective Model Risk Management for Financial Institutions: The Six Critical Components

Effective Model Risk Management for Financial Institutions: The Six Critical Components January 2013 Effective Model Risk Management for Financial Institutions: The Six Critical Components A White Paper by Brookton N. Behm, John A. Epperson, and Arjun Kalra Audit Tax Advisory Risk Performance

More information

IFRS in Asia 2008 Driving the Capital Markets of Tomorrow 10-11 October 2008, Beijing, China

IFRS in Asia 2008 Driving the Capital Markets of Tomorrow 10-11 October 2008, Beijing, China International Accounting Standards Committee Foundation, Ministry of Finance (PRC), and Shulun Pan Certified Public Accountants IFRS in Asia 2008 Driving the Capital Markets of Tomorrow 10-11, Beijing,

More information

CFO Insights How CFOs Can Own Analytics

CFO Insights How CFOs Can Own Analytics CFO Insights How CFOs Can Own Analytics Much has been made about the unprecedented quantities of data companies collect these days, from their own operations, supply chains, production processes, and customer

More information

Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization?

Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization? Chief Risk Officers in the Mutual Fund Industry: Who Are They and What Is Their Role Within the Organization? Background Everyone within an organization has some responsibility for managing risk. In the

More information

The Impact of the SarbanesOxley Act and Similar Legislation: Lessons Learned and Considerations for the Future

The Impact of the SarbanesOxley Act and Similar Legislation: Lessons Learned and Considerations for the Future The Impact of the SarbanesOxley Act and Similar Legislation: Lessons Learned and Considerations for the Future Protiviti, together with the input of the Singapore Accountancy Commission, has developed

More information

Operations Excellence in Professional Services Firms

Operations Excellence in Professional Services Firms Operations Excellence in Professional Services Firms Published by KENNEDY KENNEDY Consulting Research Consulting Research & Advisory & Advisory Sponsored by Table of Contents Introduction... 3 Market Challenges

More information

Sarbanes-Oxley Control Transformation Through Automation

Sarbanes-Oxley Control Transformation Through Automation Sarbanes-Oxley Control Transformation Through Automation An Executive White Paper By BLUE LANCE, Inc. Where have we been? Where are we going? BLUE LANCE INC. www.bluelance.com 713.255.4800 info@bluelance.com

More information

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes.

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. TECHNOLOGY BRIEF: REDUCING COST AND COMPLEXITY WITH GLOBAL GOVERNANCE CONTROLS CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. Table of Contents Executive

More information

Title here. Successful Business Model Transformation. in the Financial Services Industry. KPMG s Evolving World of Risk Management SECTORS AND THEMES

Title here. Successful Business Model Transformation. in the Financial Services Industry. KPMG s Evolving World of Risk Management SECTORS AND THEMES SECTORS AND THEMES Successful Business Model Transformation Title here in the Financial Services Industry Additional information in Univers 45 Light 12pt on 16pt leading KPMG s Evolving World of Risk Management

More information

CFO Insights: Gaining fi nancial visibility into your project portfolio

CFO Insights: Gaining fi nancial visibility into your project portfolio CFO Insights: Gaining fi nancial visibility into your project portfolio From simple research analyzing competitor data to complex ERP implementations, most work in modern corporations is done in projects.

More information

How to achieve more timely, accurate and transparent reporting through a smarter close*

How to achieve more timely, accurate and transparent reporting through a smarter close* Advisory Services How to achieve more timely, accurate and transparent reporting through a smarter close* Smart, efficient closing cycles create a foundation for evaluating performance and supporting business

More information

Corporate Resiliency Managing g the Growing Risk of Fraud and Corruption

Corporate Resiliency Managing g the Growing Risk of Fraud and Corruption Corporate Resiliency Managing g the Growing Risk of Fraud and Corruption Toby Bishop, Director, Deloitte Forensic Center Deloitte Financial Advisory Services LLP Contents Why corporate resiliency? What

More information

REGULATORY COMPLIANCE Finance Executives Call for Optimizing Processes and Systems

REGULATORY COMPLIANCE Finance Executives Call for Optimizing Processes and Systems REGULATORY COMPLIANCE Finance Executives Call for Optimizing Processes and Systems A report prepared by CFO Research Services in Collaboration with Oracle Corporation REGULATORY COMPLIANCE Finance Executives

More information

Tax data management A foundation of sustainable tax compliance, planning, and examination support

Tax data management A foundation of sustainable tax compliance, planning, and examination support Tax data management A foundation of sustainable tax compliance, planning, and examination support One of the biggest challenges for tax departments today is maintaining and being able to quickly retrieve

More information

Emerging Green Intelligence: Business Analytics and Corporate Sustainability

Emerging Green Intelligence: Business Analytics and Corporate Sustainability Emerging Green Intelligence: Business Analytics and Corporate Sustainability Background and Methodology In April 2009, BusinessWeek Research Services (BWRS) launched a research program to determine the

More information

Sarbanes-Oxley: Beyond. Using compliance requirements to boost business performance. An RIS White Paper Sponsored by:

Sarbanes-Oxley: Beyond. Using compliance requirements to boost business performance. An RIS White Paper Sponsored by: Beyond Sarbanes-Oxley: Using compliance requirements to boost business performance The business regulatory environment in the United States has changed. Public companies have new obligations to report

More information

The Transformation of Tax Something Big is Happening Here

The Transformation of Tax Something Big is Happening Here The Transformation of Tax Something Big is Happening Here Expectations of the tax function are evolving Real transformation requires a diverse team Three factors driving the transformation imperative Next

More information

Tax data analytics A new era for tax planning and compliance

Tax data analytics A new era for tax planning and compliance Tax data analytics A new era for tax planning and compliance 1 Like other business functions, tax departments face increasing demand to operate more efficiently. At the same time, expectations are growing

More information

Transforming risk management into a competitive advantage kpmg.com

Transforming risk management into a competitive advantage kpmg.com INSURANCE RISK MANAGEMENT ADVISORY SOLUTIONS Transforming risk management into a competitive advantage kpmg.com 2 Transforming risk management into a competitive advantage Assessing risk. Building value.

More information

IFAD Policy on Enterprise Risk Management

IFAD Policy on Enterprise Risk Management Document: EB 2008/94/R.4 Agenda: 5 Date: 6 August 2008 Distribution: Public Original: English E IFAD Policy on Enterprise Risk Management Executive Board Ninety-fourth Session Rome, 10-11 September 2008

More information

Talent Management in U.S. Financial Services: Attracting and Engaging Generation Y

Talent Management in U.S. Financial Services: Attracting and Engaging Generation Y Financial Services Presents: Talent Management in U.S. Financial Services: Attracting and Engaging Generation Y Andrew Liakopoulos March, 2007 Agenda What is generational talent management? The scenario

More information

The Importance of IT Controls to Sarbanes-Oxley Compliance

The Importance of IT Controls to Sarbanes-Oxley Compliance Hosted by Deloitte, PricewaterhouseCoopers and ISACA/ITGI The Importance of IT Controls to Sarbanes-Oxley Compliance 15 December 2003 1 Presenters Chris Fox, CA Sr. Manager, Internal Audit Services PricewaterhouseCoopers

More information

SOX 404 Compliance Challenges for Small Companies

SOX 404 Compliance Challenges for Small Companies A SOX2007.com White Paper SOX 404 and Small Companies: A Cost Effective Approach to 2007 Compliance Background The Sarbanes-Oxley Act (SOX) was passed by Congress in July 2002 to address corporate mismanagement

More information

Adding insight to audit Transforming internal audit through data analytics

Adding insight to audit Transforming internal audit through data analytics Adding insight to audit Transforming internal audit through data analytics Contents Why analytics? Why now?........................... 1 The business case for audit analytics................... 3 Benefits

More information

Product Life Cycle Management in Life Sciences Industry

Product Life Cycle Management in Life Sciences Industry Life Cycle Management in Life Sciences Industry Evolving from siloed to cross-functional management Audit. Tax. Consulting. Corporate Finance. A need for Lifecycle Management Life Sciences companies are

More information

Consulting. PMOver Transforming the Program Management Office into a Results Management Office

Consulting. PMOver Transforming the Program Management Office into a Results Management Office Consulting PMOver Transforming the Management Office into a Results Management Office Executive summary Regardless of size and complexity, most programs encounter hurdles and issues. Many are able to address

More information

KPMG s Financial Management Practice. kpmg.com

KPMG s Financial Management Practice. kpmg.com KPMG s Financial Management Practice kpmg.com 1 KPMG s Financial Management Practice KPMG s Financial Management (FM) practice, within Advisory Management Consulting, supports the growing agenda and increased

More information

How To Get A Tech Startup To Comply With Regulations

How To Get A Tech Startup To Comply With Regulations Agile Technology Controls for Startups a Contradiction in Terms or a Real Opportunity? Implementing Dynamic, Flexible and Continuously Optimized IT General Controls POWERFUL INSIGHTS Issue It s not a secret

More information

Third-party assurance optimization Value creation strategies for service providers

Third-party assurance optimization Value creation strategies for service providers Third-party assurance optimization Value creation strategies for service providers Introduction Not so long ago, outsourcing meant enlisting a third party to handle back-office functions such as billing

More information

GREAT PLAINS ENERGY INCORPORATED BOARD OF DIRECTORS CORPORATE GOVERNANCE GUIDELINES. Amended: December 9, 2014

GREAT PLAINS ENERGY INCORPORATED BOARD OF DIRECTORS CORPORATE GOVERNANCE GUIDELINES. Amended: December 9, 2014 GREAT PLAINS ENERGY INCORPORATED BOARD OF DIRECTORS CORPORATE GOVERNANCE GUIDELINES Amended: December 9, 2014 Introduction The Board of Directors (the Board ) of Great Plains Energy Incorporated (the Company

More information

Japanese Guidelines for Internal Control Reporting Finalized Differences in Requirements Between the U.S. Sarbanes-Oxley Act and J-SOX

Japanese Guidelines for Internal Control Reporting Finalized Differences in Requirements Between the U.S. Sarbanes-Oxley Act and J-SOX FLASH REPORT Japanese Guidelines for Internal Control Reporting Finalized Differences in Requirements Between the U.S. Sarbanes-Oxley Act and On February 15, 2007, the Business Accounting Council of the

More information

Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level

Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level August 2013 Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level A Study Conducted by Oracle and the National Association of State Auditors, Comptrollers and Treasurers

More information

An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements

An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements Examination of an Entity s Internal Control 1403 AT Section 501 An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements Source:

More information

Driving Business Value. A closer look at ERP consolidations and upgrades

Driving Business Value. A closer look at ERP consolidations and upgrades IT advisory SERVICES Driving Business Value A closer look at ERP consolidations and upgrades KPMG LLP Meaningful business decisions that help accomplish business goals and growth objectives may call for

More information

ENTERPRISE RISK MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT POLICY ENTERPRISE RISK MANAGEMENT POLICY TITLE OF POLICY POLICY OWNER POLICY CHAMPION DOCUMENT HISTORY: Policy Title Status Enterprise Risk Management Policy (current, revised, no change, redundant) Approving

More information

An Oracle White Paper October 2009. An Integrated Approach to Fighting Financial Crime: Leveraging Investments in AML and Fraud Solutions

An Oracle White Paper October 2009. An Integrated Approach to Fighting Financial Crime: Leveraging Investments in AML and Fraud Solutions An Oracle White Paper October 2009 An Integrated Approach to Fighting Financial Crime: Leveraging Investments in AML and Fraud Solutions Executive Overview Today s complex financial crime schemes pose

More information

COBIT 5 for Risk. CS 3-7: Monday, July 6 4:00-5:00. Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell.

COBIT 5 for Risk. CS 3-7: Monday, July 6 4:00-5:00. Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell. COBIT 5 for Risk CS 3-7: Monday, July 6 4:00-5:00 Presented by: Nelson Gibbs CIA, CRMA, CISA, CISM, CGEIT, CRISC, CISSP ngibbs@pacbell.net Disclaimer of Use and Association Note: It is understood that

More information

Compliance in motion A closer look at the Corporate Sector. Deloitte Risk Services March 2015

Compliance in motion A closer look at the Corporate Sector. Deloitte Risk Services March 2015 Compliance in motion A closer look at the Corporate Sector Deloitte Risk Services March 2015 2 Contents Preface 5 Management summary 6 The compliance culture 7 Compliance priorities for the next five years

More information

Corporate Secretarial Services Your guide to corporate compliance

Corporate Secretarial Services Your guide to corporate compliance Corporate Secretarial Services Your guide to corporate compliance 2 Corporate Secretarial Services assists clients to manage and mitigate risks of corporate non-compliance. Innovative techniques coupled

More information

Beyond risk identification Evolving provider ERM programs

Beyond risk identification Evolving provider ERM programs Beyond risk identification Evolving provider ERM programs March 2016 At a glance PwC conducted research to assess the state of enterprise risk management (ERM) within healthcare providers and found many

More information

Empower your talent with learning

Empower your talent with learning Empower your talent with learning The Standard of Excellence Talent, knowledge, skills, and expertise are critical to achieving the Deloitte Touche Tohmatsu ( DTT ) vision for the decade 2010 to be the

More information

How Insurance Companies Can Beat the Talent Crisis

How Insurance Companies Can Beat the Talent Crisis Financial Services How Insurance Companies Can Beat the Talent Crisis Staying competitive through integrated talent management How Insurance Companies Can Beat the Talent Crisis Staying competitive through

More information

March 2015. Internal audit insights High impact areas of focus

March 2015. Internal audit insights High impact areas of focus March 2015 Internal audit insights High impact areas of focus Introduction Internal audit is widely, if not universally, viewed as a key pillar in effective governance with expectations of internal audit

More information

2004 Consumer-Driven Health Care Survey

2004 Consumer-Driven Health Care Survey Survey Synopsis 2004 Consumer-Driven Health Care Survey Background Health care cost increases were once again in the double-digit range for the majority of companies for the third consecutive year. Companies

More information

RSA ARCHER AUDIT MANAGEMENT

RSA ARCHER AUDIT MANAGEMENT RSA ARCHER AUDIT MANAGEMENT Solution Overview INRODUCTION AT A GLANCE Align audit plans with your organization s risk profile and business objectives Manage audit planning, prioritization, staffing, procedures

More information

STANDING ADVISORY GROUP MEETING

STANDING ADVISORY GROUP MEETING 1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org RISK ASSESSMENT IN FINANCIAL STATEMENT AUDITS Introduction The Standing Advisory Group ("SAG")

More information

White Paper March 2009. Consolidation automation Advancing compliance and performance management

White Paper March 2009. Consolidation automation Advancing compliance and performance management White Paper March 2009 Consolidation automation Advancing compliance and performance management 2 Contents 3 Business problems 3 Business drivers Consolidation: At the core of compliance and performance

More information

Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security,

Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security, Symantec Security Compliance Solution Symantec s automated approach to IT security compliance helps organizations minimize threats, improve security, streamline compliance reporting, and reduce the overall

More information

Information about 2015 Inspections

Information about 2015 Inspections Vol. 2015/2 October 2015 Staff Inspection Brief The staff of the Public Company Accounting Oversight Board ( PCAOB or Board ) prepares Inspection Briefs to assist auditors, audit committees, investors,

More information

ENTERPRISE RISK MANAGEMENT FRAMEWORK

ENTERPRISE RISK MANAGEMENT FRAMEWORK ENTERPRISE RISK MANAGEMENT FRAMEWORK COVENANT HEALTH LEGAL & RISK MANAGEMENT CONTENTS 1.0 PURPOSE OF THE DOCUMENT... 3 2.0 INTRODUCTION AND OVERVIEW... 4 3.0 GOVERNANCE STRUCTURE AND ACCOUNTABILITY...

More information